CVE-2017-8288
Last modified
CVE-2017-8288 is a vulnerability of currently unknown severity. gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. EPSS estimates a 2.94% chance of exploitation in the next 30 days.
Description
gnome-shell 3.22 through 3.24.1 mishandles extensions that fail to reload, which can lead to leaving extensions enabled in the lock screen. With these extensions, a bystander could launch applications (but not interact with them), see information from the extensions (e.g., what applications you have opened or what music you were playing), or even execute arbitrary commands. It all depends on what extensions a user has enabled. The problem is caused by lack of exception handling in js/ui/extensionSystem.js.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Gnome-Shell | 3.22.0 |
| Gnome | Gnome-Shell | 3.22.1 |
| Gnome | Gnome-Shell | 3.22.2 |
| Gnome | Gnome-Shell | 3.22.3 |
| Gnome | Gnome-Shell | 3.23.1 |
| Gnome | Gnome-Shell | 3.23.2 |
| Gnome | Gnome-Shell | 3.23.3 |
| Gnome | Gnome-Shell | 3.23.90 |
| Gnome | Gnome-Shell | 3.23.91 |
| Gnome | Gnome-Shell | 3.23.92 |
| Gnome | Gnome-Shell | 3.24.0 |
| Gnome | Gnome-Shell | 3.24.1 |
References
- http://www.securityfocus.com/bid/98070Third Party Advisory, VDB Entry
- https://bugs.kali.org/view.php?id=2513Issue Tracking
- https://bugzilla.gnome.org/show_bug.cgi?id=781728Issue Tracking
- https://github.com/EasyScreenCast/EasyScreenCast/issues/46Third Party Advisory
- https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1Issue Tracking, Patch, Third Party Advisory
- http://www.securityfocus.com/bid/98070Third Party Advisory, VDB Entry
- https://bugs.kali.org/view.php?id=2513Issue Tracking
- https://bugzilla.gnome.org/show_bug.cgi?id=781728Issue Tracking
- https://github.com/EasyScreenCast/EasyScreenCast/issues/46Third Party Advisory
- https://github.com/GNOME/gnome-shell/commit/ff425d1db7082e2755d2a405af53861552acf2a1Issue Tracking, Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-8288?
How severe is CVE-2017-8288?
How do I fix CVE-2017-8288?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-8280In all Qualcomm products with Android releases from CAF usin…
- CVE-2017-8281In all Qualcomm products with Android releases from CAF usin…
- CVE-2017-8282XnView Classic for Windows Version 2.40 allows user-assisted…
- CVE-2017-8283dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a n…
- CVE-2017-8284The disas_insn function in target/i386/translate.c in QEMU b…
- CVE-2017-8287FreeType 2 before 2017-03-26 has an out-of-bounds write caus…
- CVE-2017-8289Stack-based buffer overflow in the ipv6_addr_from_str functi…
- CVE-2017-8290A potential Buffer Overflow Vulnerability (from a BB Code ha…
- CVE-2017-8291Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass…7.8
- CVE-2017-8294libyara/re.c in the regex component in YARA 3.5.0 allows rem…
- CVE-2017-8295WordPress through 4.7.4 relies on the Host HTTP header for a…
- CVE-2017-8296kedpm 0.5 and 1.0 creates a history file in ~/.kedpm/history…
Are you affected by CVE-2017-8288?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
